Skip to content

SEARCH-3102 add semantic search to bdk (#374) - #402

Merged
sebastientosello merged 11 commits into
finos:release/3.xfrom
broHeryk:SEARCH-3102-semantic-search-3x
Sep 10, 2026
Merged

sebastientosello merged 11 commits into
finos:release/3.xfrom
broHeryk:SEARCH-3102-semantic-search-3x

Conversation

@broHeryk

@broHeryk broHeryk commented Sep 1, 2026 •

Copy link
Copy Markdown
Collaborator

Description

Closes SEARCH-3102

We've got ability to use semantic search instead alongside exact match search. This PR adds a method to handle it.

Dependencies

None

Checklist

  • Referenced an issue in the PR title or description
  • Filled properly the description and dependencies, if any
  • Unit tests updated or added
  • Docstrings added or updated
  • Updated the documentation in docsrc folder

@broHeryk
broHeryk changed the base branch from main to release/3.x September 1, 2026 14:20
@broHeryk
broHeryk force-pushed the SEARCH-3102-semantic-search-3x branch from 3ba4ebc to 3a439fd Compare September 1, 2026 14:36
@broHeryk broHeryk changed the title CAIP-99 Regenerate code using latest openapi generator (#374) SEARCH-3102 add semantic search to bdk (#374) Sep 1, 2026
@broHeryk
broHeryk force-pushed the SEARCH-3102-semantic-search-3x branch from 13c3b1d to ac7a29e Compare September 2, 2026 08:10
@matthewcummings
matthewcummings self-requested a review September 4, 2026 15:49
@sebastientosello

Copy link
Copy Markdown
Contributor

Lets take a different path to get 3.x aligned with main branch and ship the semantic search bit. Here is what we can do ;

  • Lets replace this PR against 3.x branch with only the semantic search related work
  • I will create branch and tag of current main as 2.x
  • Then lets open a PR from 3.x to main and push a beta release for internal testing/best effort validation

matthewcummings and others added 9 commits September 9, 2026 18:06
* Raise cryptography ceiling to allow the patched 50.x

The current constraint, cryptography>=48.0.1,<49.0.0, cannot resolve to a
version free of known CVEs:

  48.0.1  CVE-2026-69247 and CVE-2026-69249
  49.0.0  CVE-2026-69247
  50.0.x  clean

Both CVEs were published 2026-08-03, before 2.11.3 was released, so every
version the released constraint permits is affected. Downstream consumers
cannot work around this: anything satisfying the BDK is vulnerable, and
anything patched fails resolution. It surfaces as a hard failure in image
compliance scanning.

This is the second time in eight days the ceiling has blocked a security
fix. finos#397 raised it from <47.0.0 to <49.0.0 for CVE-2026-34180, and it is
already stale again.

Verified: the full test suite passes on the new lock and identically on
the old pin, so this is not masking a regression.

  cryptography 48.0.1  560 passed, 3 skipped
  cryptography 50.0.0  560 passed, 3 skipped
  cryptography 50.0.1  560 passed, 3 skipped   (the locked version)

poetry.lock regenerated with Poetry 2.4.2; cryptography 48.0.1 to 50.0.1
is the only package change, none added or removed.

* Bump version to 2.11.4 to prepare a patch release

Included here so merging this PR leaves main release-ready, rather than
needing a second PR before the fix can reach consumers.

The constraint fix in finos#390 sat unreleased for five days because the
version bump was a separate change (finos#397). The CVEs this PR addresses
are live in the released 2.11.3, so the gap matters.

Follows the same convention as finos#397: pyproject.toml only. The lock is
unaffected, project version is not part of its content hash.

(cherry picked from commit 487ac1c)
…ates

Reconciles the lock file with the dependency changes cherry-picked from
finos/main (finos#381 snyk updates, finos#399 cryptography ceiling) on top of the
3.x pydantic/aiohttp-retry additions.
@broHeryk
broHeryk force-pushed the SEARCH-3102-semantic-search-3x branch 2 times, most recently from 77c2bfe to 8784fad Compare September 9, 2026 15:42
@broHeryk
broHeryk force-pushed the SEARCH-3102-semantic-search-3x branch from 8784fad to ebfb75c Compare September 9, 2026 15:56
@sebastientosello
sebastientosello merged commit 32b718f into finos:release/3.x Sep 10, 2026
19 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants